Malware

About “Downloader.Win32.Agent.mqne” infection

Malware Removal

The Downloader.Win32.Agent.mqne is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mqne virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

How to determine Downloader.Win32.Agent.mqne?


File Info:

crc32: 0531E2EC
md5: d0798b5a86af0cd8c2984afaf79005a4
name: D0798B5A86AF0CD8C2984AFAF79005A4.mlw
sha1: 4c18783e59d7b4efe847529c94a0e8c0f81cc533
sha256: 410ab050185d3dd4b712962f382fe934db59959b75e85c48d914675215149acd
sha512: ea6a4d9b32278102b5ea29799a52bddc92a7fc9f4d89102ae3b1b32ad2be2da27dc2b3cfcd5eeb9f1cf1cbceb339e71476a9cfe5276554ae2942e9f153d781d4
ssdeep: 24576:+bvi4V34Dz+rmL9g87480Uh4TEKpe5JY5PhOOd0:P4OfCk287h4TCbY5PhOOd0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: FastDownloader.exe
FileVersion: 3.2.0.8
CompanyName: -
ProductName: x8f6fx4ef6x4e0bx8f7dx5668
ProductVersion: 3.2.0.8
FileDescription:
OriginalFilename: FastDownloader.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mqne also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebAdware.Downware.19825
CynetMalicious (score: 100)
ALYacGen:Variant.Application.Graftor.928385
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaDownloader:Win32/Downer.0376b321
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.a86af0
CyrenW32/Application.CCFT-8818
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
Kasperskynot-a-virus:Downloader.Win32.Agent.mqne
BitDefenderGen:Variant.Application.Graftor.928385
MicroWorld-eScanGen:Variant.Application.Graftor.928385
Ad-AwareGen:Variant.Application.Graftor.928385
SophosGeneric PUA EM (PUA)
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.d0798b5a86af0cd8
EmsisoftGen:Variant.Application.Graftor.928385 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Adware.Gen
eGambitUnsafe.AI_Score_96%
MicrosoftPUA:Win32/Downer
GridinsoftAdware.Agent.sd!c
ArcabitTrojan.Application.Graftor.DE2A81
GDataGen:Variant.Application.Graftor.928385
AhnLab-V3PUP/Win32.RL_Downloader.R367892
McAfeeGenericRXAA-AA!D0798B5A86AF
MAXmalware (ai score=73)
VBA32Downloader.Agent
MalwarebytesPUP.Optional.ChinAd
PandaTrj/Genetic.gen
RisingAdware.Downloader!1.CB5D (CLOUD)
IkarusPUA.RiskWare.Downer
FortinetRiskware/Downer.DD89
AVGWin32:DropperX-gen [Drp]

How to remove Downloader.Win32.Agent.mqne?

Downloader.Win32.Agent.mqne removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment